10 ms·
Really? Have there been any cases yet? I'm asking cuz I started devloping a c2+agent+BOF kind of thing with custom bytecode vm for the lulz (to learn how stuff
by RamblingCTO 2mo ago
Really? Have there been any cases yet?
I'm asking cuz I started devloping a c2+agent+BOF kind of thing with custom bytecode vm for the lulz (to learn how stuff works nowadays) and it's on tangled and github :/
- sdoering 2mo agoYes. More than one. This one was especially "interesting", a security researcher was tasked by a company to evaluate the ERP (I believe would be the acronym) software. Diiscovered an external database connection, looked at it, discovered this external DB contained sensitive information from other clients of that vendor - reported it, got sued, lost. In German: https://ht-strafrecht.de/blog/strafrecht/it-sicherheitsluecke-entdeckt-und-verurteilt-der-fall-eines-it-experten-und-die-grenzen-des-hacker-paragraphen/ https://ht-strafrecht.de/blog/strafrecht/it-sicherheitslueck...
- RamblingCTO 2mo agoOuch, that's pathetic. Hm, maybe I'll leave it then. Not worth the hassle. Although I don't really think someone would hunt me for random non-prod github repos
- voodooEntity 2mo agoYe you should be really careful on that one. If just somebody with a bad mood reports you, even if you have absolutely good intentions, it can cost you and if its just in spendings in a lawyer to proof that your fine....